Pokemon Go APK Could Hijack Your Phone: How to Check If It's Genuine

Advertisement
By Rishi Alwani | Updated: 29 July 2016 13:43 IST
Highlights
  • Pokemon Go isn't available outside Australia, New Zealand, and the US
  • This has led to many to get the game via third-party sites
  • However some APKs may be able to take control of your device

Until Pokemon Go makes it way to countries outside of Australia, New Zealand, and the US, a vast majority of eager fans have little choice but to resort to obtaining the game through unofficial means, which means downloading the APK file. It's something we've outlined in this handy guide for Android users.

In the event you've obtained Pokemon Go through other sites, there's a chance it might not be the right APK. According to security software company Proofpoint, a malicious version of the game has been uploaded to various APK download sites.

Advertisement

(Also see: How to Download, Install, and Play Pokemon Go Right Now)

"This specific APK was modified to include the malicious remote access tool (RAT) called DroidJack (also known as SandroRAT), which would virtually give an attacker full control over a victim's phone. The DroidJack RAT has been described in the past, including by Symantec and Kaspersky. Although we have not observed this malicious APK in the wild, it was uploaded to a malicious file repository service at 09:19:27 UTC on July 7, 2016, less than 72 hours after the game was officially released in New Zealand and Australia," the firm said.

Advertisement

This means that there's chance that the Pokemon Go APK you downloaded is a fake, and could give anonymous individuals complete access to your phone. Here's how you can tell if the Pokemon Go APK you've downloaded is RAT-free.

(Also see: Pokemon Go Tips and Tricks)

Method 1: check the SHA-256 of your file.

The Secure Hash Algorithm or SHA is a string of characters unique to specific data. It's a way to check if a file has been altered or not by acting like a signature for a text or data file.

To calculate the SHA-256 hash of your Pokemon Go APK this is what you need to do:

Advertisement
  1. Obtain Hash Droid from the Play Store.
  2. Select Hash A File.
  3. Under Select a hash function, choose SHA-256.
  4. Choose the Pokemon Go APK from your Download folder.
  5. Hit Calculate.
  6. If safe you should get: 5a8679e3e4298b7b3ffac725106db12a21bdb0bcf746f44fa7e46c40dbf794aa

At the time of posting this, no updated versions of Pokemon Go have been released so it is safe to assume any other SHA-256 hash belongs to a malicious APK.

(Also see: Playing Pokemon Go in India? Here's Everything You Need to Know)

As per Proofpoint, the SHA-256 of one of the malicious APKs is 15db22fd7d961f4d4bd96052024d353b3ff4bd135835d2644d94d74c925af3c4

Advertisement

Method 2: Check app permissions

  1. On your Android device go to Settings -> Apps -> Pokemon Go
  2. View the Permissions section.
  3. Here's what it should be asking permission for:


(Also see: Pokemon Go Is Responsible for These Real Life Weird and Scary Things)

And here's what one of the malicious Pokemon Go APK asks for:

(Also see: Pokemon Go Cheatsheet: 10 Things to Know About the Game That Has Everyone Hooked)

As you can see, it would ask for access to your call logs, record audio, check your browsing history, and even send messages and make calls on your behalf. Scary.

Hopefully Niantic and The Pokemon Company rectify this by making Pokemon Go available to all regions soon. Till then though we'd advise caution prior to downloading.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Microsoft Unveils Surface Laptop Ultra as Its Most Powerful Laptop to Date
  2. Aspire X 16 AI, Aspire 18 AI Debut Alongside New All-in-One Desktops
  3. Apple's Meta Ray-Ban Rivalling Smart Glasses Delayed Till Next Year
  4. HP OmniBook X 14, Ultra 16 Refreshed With Nvidia RTX Spark 'Superchip'
  5. Vivo X Fold 6 Launch Timeline, Key Specifications Leaked Online
  6. Acer Predator Helios 18 AI (2026) Debuts With an Intel Core Ultra 9 CPU
  1. Vivo X Fold 6 Launch Timeline Leaked; Tipped to Arrive With MediaTek Dimensity 9500 Chip
  2. HP OmniBook Ultra 16 (2026), OmniBook X 14 (2026) Unveiled With Nvidia's RTX Spark 'Superchip'
  3. Acer Swift Air 14 Launched With Intel Core Series 3 CPU, Lightweight Design at Computex 2026
  4. Microsoft Surface Laptop Ultra Announced With Blackwell RTX GPU, Nvidia RTX Spark Superchip
  5. Acer Aspire X 16, Aspire 18 AI Copilot+ PCs Launched Alongside Aspire C27 AI, Aspire C24 AI All-in-One Desktops
  6. Acer Predator Helios 18 AI (2026) Launched With Intel Core Ultra 9 CPU, Up to Nvidia GeForce RTX 5090 GPU
  7. Computex 2026: Samsung Display to Showcase 4K 360Hz QD-OLED, Handheld Gaming OLED Panels
  8. Unreleased Beats Headphones Spotted in Lamine Yamal's Instagram Post After Visiting US FCC Database
  9. Google Drive's Document Scanner Gets Major Refresh With Support for Detecting Duplicates, Multiple Page Scanning
  10. Dell XPS 13 (2026) Launched With 2.5K Display, Up to Intel Core Ultra 7 Series 3 Processor: Price, Specifications
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.